Microsoft said a server-side Bing update intended to improve search performance caused Start Menu search failures for a small number of Windows 11 23H2 devices, leaving some users with blank search panels or queries that would not return results. The issue was tracked as WI1273488 and was acknowledged on the Windows Release Health dashboard after users began reporting problems.
The company resolved the disruption by rolling back the faulty server-side change, meaning affected systems did not require a separate software update. Microsoft said the fix should reach impacted devices automatically, but systems must be connected to the internet and cannot have Web Search disabled through Group Policy to receive it. The incident also renewed attention on broader Start Menu reliability problems in Windows 11, including a separate unresolved bug tied to cumulative updates that has caused crashes in the Start Menu, File Explorer, and other shell components due to XAML package registration failures.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft mitigated the Windows 11 23H2 Start Menu search problem by rolling back the faulty server-side Bing update. The company said affected devices would recover automatically once the fix propagated, provided they were online and Web Search was not disabled by Group Policy.
A server-side Bing update intended to improve search performance began causing Start Menu search failures for a small number of Windows 11 23H2 users, producing blank search panels or failed queries. Microsoft tracked the issue as WI1273488.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.